ISO 22301, measured against what the last test actually achieved
A recovery time objective written in a document is a target. ISO 22301 asks you to prove it, through a business impact analysis that justifies it and an exercise programme that tests it. Dimeri holds the analysis, the plan and the test result as one record.
What ISO 22301 requires
ISO 22301 specifies requirements for a business continuity management system. Like ISO 27001 it follows the common management system structure, clauses 4 to 10, and it is certifiable, so each shall is tested by an auditor. The 2019 revision simplified the wording and clarified the relationship between the business impact analysis and the risk assessment.
Clause 8.2 carries the analytical core. The business impact analysis identifies activities that support the delivery of products and services, assesses the impact over time of not performing them, and from that derives prioritised timeframes for resumption. Those timeframes are where recovery time objectives come from. A risk assessment then identifies what could disrupt those prioritised activities. The order matters: the impact analysis tells you what to protect, and the risk assessment tells you what to protect it from.
Clause 8.3 requires business continuity strategies and solutions chosen against those requirements, clause 8.4 requires plans and procedures with defined activation criteria and roles, and clause 8.5 requires an exercise programme. That last one is where certified organisations most often fall down: plans exist, exercises are scheduled, and the shortfalls the exercise exposed never become tracked actions.
The clauses Dimeri tracks
Dimeri holds the impact analysis, the dependencies, the plans and the exercise results as one connected record rather than four documents that age apart.
Context, scope and leadership
The scope of the management system defined against the products and services it protects, with top management accountable for it.
- Scope held with the activities and sites it covers
- Interested parties and their continuity requirements
- Business continuity policy with review dates
- Roles, responsibilities and authorities assigned
Business impact analysis
Prioritised activities identified, the impact of their disruption assessed over time, and resumption timeframes derived from that impact rather than chosen.
- Activities recorded with the products they support
- Impact over time captured against agreed categories
- Recovery time and point objectives derived and justified
- Dependencies on people, systems, suppliers and sites
Risk assessment
The disruption risks to prioritised activities identified and assessed, using the same method as the wider risk register rather than a parallel one.
- Disruption risks scored on the organisation's own criteria
- Single points of failure surfaced across activities
- Treatment actions with owners and due dates
- Residual position reassessed after treatment
Strategies, solutions and plans
Continuity strategies selected against the requirements the impact analysis set, with plans carrying activation criteria, roles and contacts.
- Strategy recorded per prioritised activity
- Plans held with owners and review cycles
- Activation criteria and escalation defined
- Contact and resource lists kept current
Exercise programme
Exercises that test the plans against their stated objectives, with results recorded and shortfalls acted on.
- Exercise calendar with scope and type per test
- Actual recovery measured against the objective
- Shortfalls raised as owned actions, not observations
- Post exercise reports drawn from the record
Evaluation and improvement
Performance evaluation, internal audit, management review, and corrective action on nonconformities.
- Internal audit programme covering the whole BCMS
- Management review inputs gathered through the year
- Nonconformities tracked with root cause to closure
- Improvement actions on the system, not just the plans
How Dimeri covers ISO 22301
The gap in most continuity systems is between the plan and the evidence it works. Dimeri closes it by treating the exercise result as data rather than a report.
Objectives traceable to the analysis
Every recovery time objective links back to the impact assessment that produced it. When an auditor asks why four hours rather than twelve, the answer is the analysis rather than an opinion.
Exercises that produce actions
What the test achieved is recorded against what the plan promised, and every shortfall becomes an owned action with a date. That is the difference between an exercise programme and a filing exercise.
Dependencies mapped once
The systems, suppliers, sites and people each activity relies on are recorded once and reused by third party risk and operational risk, so the analysis earns its cost three times over.
Shared clauses with ISO 27001
Context, leadership, competence, documented information, internal audit and management review are common management system clauses. Organisations certified to both run one system with two scopes rather than two systems.
Getting ISO 22301 in place
- 1
Scope against products and services
The scope is defined by what the organisation must keep delivering, not by departments. Getting this wrong is the most common reason a first certification attempt stalls.
- 2
Run the impact analysis first
Prioritised activities and their impact over time come before any discussion of solutions. Recovery objectives fall out of that analysis rather than being set by whoever is loudest.
- 3
Choose strategies and write plans
Continuity solutions are selected against the requirements the analysis set, and plans carry activation criteria, roles and contacts, each with a named owner and a review cycle.
- 4
Exercise, measure, improve
The exercise programme tests plans against their objectives, shortfalls become tracked actions, and internal audit and management review keep the system running between certification visits.
ISO 22301 questions
What is the difference between the business impact analysis and the risk assessment?
The impact analysis asks what the organisation must resume and how quickly, by assessing the consequence over time of not performing each activity. The risk assessment then asks what could disrupt those prioritised activities. The analysis identifies what to protect; the assessment identifies what to protect it from. ISO 22301 requires both, in that order.
Do we need to be certified to use ISO 22301?
No. Many organisations align to the standard for the structure it provides without seeking certification, and its clauses work perfectly well as an internal discipline. Certification matters mainly when a client, regulator or insurer asks for independent assurance.
How often do plans need to be exercised?
The standard requires an exercise programme rather than a fixed frequency, leaving the organisation to justify a schedule proportionate to the activity's priority. Most set annual exercises for the highest priority activities with lighter walkthroughs in between. Dimeri enforces whichever cycle you set and shows when it slips.
How does this relate to the business continuity module?
This page describes the standard; the business continuity platform page covers the product in more depth, including the recovery objective tracking and dependency mapping. Both draw on the same underlying record.
Is this a substitute for the standard itself?
No. ISO 22301 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.
Go further on ISO 22301
Put ISO 22301 on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.